AI
Why India Called Telegram a Dark Web Hub: The Privacy Paradox
India's government just called Telegram a hub for bad actors the same app 900 million people use to share memes and run businesses. Here's the real clash nobody is talking about.

India's government recently compared Telegram to the dark web. Not a fringe app. Not some encrypted tool used by three people in a basement. Telegram, the app on your phone right now, probably in a folder next to WhatsApp.
The official framing: Telegram is a 'hub for bad actors.' A place where criminals hide. A threat to public order.
Here's what that framing hides: the same feature that makes Telegram useful to a drug cartel also makes it useful to a whistleblower, a journalist, a startup founder sharing early product ideas, or a student in a city with a controlling family.
The state didn't call out a feature. It called out a philosophy. And that's a very different problem.
You cannot have a door that is locked for everyone except the right person because once you build that door, every wrong person will eventually find the key.
The Pattern
This is not really about Telegram. It never is.
Every few years, a privacy tool gets popular enough that governments notice it. End-to-end encryption gets labeled a criminal shield. Anonymous browsing gets linked to terrorism. Strong passwords get called suspicious. The pattern is consistent: when a tool reaches scale, the state needs to decide whether it can see inside it.
Telegram's specific design, large group chats, minimal data collection, channels that can reach millions, made it genuinely useful for organizing. Protests. Communities. Businesses. And yes, scams and worse.
The Indian government's response wasn't to target the bad actors using Telegram. It was to question whether Telegram itself should exist in its current form. That's the tell. When you can't see inside a room, the easiest move is to say the room is dangerous.
The Mechanism
What's driving this is a clash between two trust models that cannot both win.
The first is user trust in encryption. The logic: I control my data. No one reads my messages without my consent. The system works because it is closed.
The second is state trust in centralized control. The logic: safety requires visibility. If we cannot see what is happening, we cannot stop harm. The system works because it is open to authority.
These two models are not just different. They are structurally incompatible. You cannot have a door that is locked for everyone except the right person, because once you build that door, every wrong person will eventually find the key.
This is where the zero-sum fallacy kicks in. Zero-sum fallacy is the belief that one side's gain must be another's loss. Here, the state treats every byte of privacy as a byte of safety lost. But that's not how it works. Encryption that protects a criminal also protects a domestic abuse survivor hiding from her husband. You cannot surgically remove one use case.
Think of it like this: your building's security guard can either check every bag or trust residents. The moment he starts checking every bag, the residents stop being residents. They become suspects. The building still stands, but something important broke.
The Evidence Behind the Telegram Debate
Telegram has faced regulatory pressure across multiple countries not just India. France arrested Telegram's founder Pavel Durov in 2024, citing the platform's failure to cooperate with law enforcement on criminal investigations. That arrest sent a signal to every privacy-forward platform: scale makes you a target.
India's IT Ministry has previously issued takedown orders to platforms and used intermediary liability rules to compel data sharing. The legal architecture already exists. What's new is the framing calling a mainstream platform a dark web equivalent is a rhetorical escalation, not just a legal one.
The dark web comparison matters because it is designed to do one thing: shift public opinion before legislation moves. If enough people believe Telegram is where criminals live, fewer people will object when access is restricted or backdoors are mandated.
This playbook has been used before. It will be used again.
The Consequence
If you are building anything in India that touches user data, communication, or privacy this story is not background noise. It is a preview.
The regulatory risk is not theoretical. A platform can be compliant today and non-compliant tomorrow because the rules shifted, not because the product changed. Builders who treat privacy as a pure UX feature something users want are missing the second variable: privacy is also a political surface that governments push against.
For users, the cost is subtler but real. The moment you know someone might be watching, you change what you say. You self-censor. You move conversations. You fragment your communication across five apps instead of one. This is called the chilling effect when the possibility of surveillance changes behavior even before any actual surveillance happens.
Think about the family WhatsApp group. You have probably edited a message before sending it, not because it was wrong, but because you imagined who might screenshot it. Now scale that instinct to every conversation you have about money, health, politics, or work. That is what normalized surveillance does to a population.
For builders, the specific danger is building on top of platforms that have not resolved this tension. If Telegram gets regulated heavily tomorrow, every product built on its API or its community infrastructure takes the hit with it.
The Decode
Here is what is actually happening, stripped of the politics.
The state is not lying when it says Telegram is used by bad actors. It is. So is email. So is the telephone. The question is never whether a tool can be misused. The question is whether the cost of restricting it falls equally on everyone.
It does not. It never does. The person with resources, lawyers, and alternatives moves to a different tool. The person without those things, the activist, the small business owner, the person in a bad situation trying to communicate safely loses the tool and has nowhere to go.
If you are building a product with any privacy component, you need to make a deliberate choice now, not when the regulator comes knocking. Do you build for compliance-first, which means designing around what the state can see? Or do you build for user trust-first, which means being ready to defend that choice publicly and legally?
Neither answer is wrong. But pretending you do not have to choose is the most expensive mistake you can make.
The encryption debate will not be settled by a court ruling or a government press release. It will be settled by what users accept and what builders are willing to defend. Right now, most builders are watching. That is also a choice.
Privacy is not a feature you add at the end. It is a political position you hold from the beginning and the state will eventually ask you to justify it.
So here is the question worth sitting with: if the platform you are building on, or the app you rely on most, had to choose between its users and its operating license tomorrow which way do you think it goes?
Sources & References
- Internet Pulse · Inc42 — original story
- India Legal — Centre defends Telegram ban before Delhi High Court, warns of NEET paper leak risks
- LawChakra — How Can We Stop 150 Million People's Rights Because Some Are Appearing In Exams?: Delhi HC Questions Telegram Ban, Reserves Verdict
- "Chilling effect" — Wikipedia
- "Zero-sum thinking" — Wikipedia
Decoded by anupam.decoded — Decoding AI, Business & Human Behaviour
Instagram · LinkedIn · Website